Former CISO of Pentalog, Logan Fernandez co-founded Tales of Security in 2024. This Breton start-up is developing a solution that financially quantifies cyber risks. He explains why this approach helps CISOs better defend their budgets to executive committees.
JDN. The solution you co-founded, Tales of Security, makes it possible to quantify cyber risks in euros. How did you get this idea ?
Logan Fernandez. When I was CISO of a large company, I had to present to the executive committee (comex) the cyber risks it was facing and request a budget to avoid them. For this, I used the traditional method that every French CISO knows. This assesses the seriousness of a risk and its probability of occurring on a scale of 1 to 16, based on a certain number of rather subjective criteria. However, I realized that it did not allow me to attract enough attention from the other members of the executive committee to ask them for a budget. They used business-oriented language, while I spoke cyber and technical language. This had to change.
What did the Comex criticize about this method?
The value of cyber risks that I indicated was perceived as too subjective and abstract by the members of the executive committee. Furthermore, they did not understand the very operational vocabulary that I used to justify my choice of value. For example, they didn’t understand why I assigned a value of 12 rather than 8 to this or that risk. It was therefore difficult to propose a budget to avoid a risk that they had difficulty quantifying.
This is why I made the decision to replace these abstract values with euros. At least it’s concrete and we can better understand the value of the risk. By using the same unit of measurement for both risk and budget, I saw that I finally had the attention of the entire executive committee, because I spoke their language. Above all, it allowed me to calculate the return on investment and demonstrate that the budgets I requested allowed the organization to save money. By quantifying the risks in euros, the CISO convinces the executive committee that cybersecurity is not a cost but an investment.
How can cyber risk be quantified?
You must use the so-called Factor analysis of information risk (Fair) method, which was created in the United States by a CISO, Jack Jones, more than twenty years ago. Unlike the traditional qualitative method I used, it is quantitative. It breaks down risk into several measurable factors and uses statistics and probabilities to financially quantify risk based on logical and verifiable scenarios. The Tales of Security solution makes it possible to simplify its implementation in organizations, by structuring the analysis using the data provided.
Concretely, how does this method work?
Rather than assessing the severity of cyber risk subjectively, it analyzes it from very pragmatic angles to estimate its financial value. For example, it makes it possible to estimate the amount of money that cyber risk costs in productivity if it occurs. To calculate this, we therefore determine the number of employees who will be unemployed if it occurs, and for how long. We can also measure the impact of the incident on the operating loss using the data available to the organization, such as its daily turnover.
We can also calculate the contractual penalties that the organization must pay to its customers if cyber risk prevents it from providing its goods and services. Legal penalties can also be quantified, such as fines from the CNIL in the event of non-compliance with the GDPR, etc. This method also makes it possible to quantify the cost of a cyber incident in terms of reputation. To do this, we rely on statistics from insurance firms which measure the drop in the conversion rate from prospects to customers following a major incident. By cross-checking these statistics with data from the sales and marketing teams, it is therefore possible to measure the number of prospects who will not become customers. The cost in terms of reputation can thus be quantified financially.
What is the feedback from your customers who adopt this method?
Our clients, who are mainly large SMEs, mid-sized companies and sometimes large companies, often explain that this quantification of risk gives new meaning to cybersecurity professions. The CISO who uses it is no longer confined only to operational matters. He also serves the business interests of his organization and communicates with other professions, such as marketing or sales. He therefore becomes more aware that he is participating in the sustainability of the company, its primary mission.